IT Security Gateway for Legacy Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial technological systems face challenges in maintaining IT security due to obsolete automated control systems, lack of regular updates, and inadequate security measures, leading to vulnerabilities from malicious actions and unintentional mistakes, which can disrupt processes and introduce errors.
Innovation Solution
A method and system for stepwise increasing IT security by intercepting traffic between elements, identifying vulnerable components, analyzing their severity, and operating the most vulnerable parts in a protected environment using a hypervisor mode to ensure secure data exchange and control, while maintaining system functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If obsolete automated control systems are used in technological systems, then system compatibility and operational stability are maintained, but IT security and protection against malicious actions deteriorate
Solution Approach 1:
A security gateway is introduced as an intermediary component between the obsolete automated control system and the external network. The gateway intercepts all communications, analyzes them for security threats, and filters malicious actions while allowing legitimate operations to pass through, thus protecting the legacy system without disrupting its operational stability
Solution Approach 2:
The technological system is segmented into isolated zones with different security levels. The obsolete control system operates in a restricted zone separated from the external network by security gateways, allowing the system to maintain its legacy functionality while being protected from external threats through architectural isolation
2Object-affected harmful factors
If frequent updates of control systems are performed to improve security, then IT security is improved, but system interruptions and operational disruptions increase
Solution Approach 1:
Security updates and patches are applied in advance to the security gateway and protective software components before they are needed to counter actual attacks. This allows the system to maintain security improvements without interrupting the operational processes, as the protective measures are pre-installed and ready
3Adaptability or versatility
If existing obsolete automated control systems are connected to computer networks to enable data exchange, then system connectivity and data sharing are improved, but security against external malicious actions deteriorates
Solution Approach 1:
Security gateways serve as intermediary components that enable network connectivity for obsolete control systems while filtering out malicious actions. The gateways allow legitimate data exchange and communication with external networks while blocking security threats, thus achieving both connectivity and security
Solution Approach 2:
The security protection functions are extracted from the obsolete control system itself and placed in separate security gateway components. This allows the legacy system to maintain its original simplicity and functionality while security concerns are handled by dedicated protective infrastructure
4Object-affected harmful factors
If comprehensive security measures are implemented in existing control systems, then protection level is improved, but system complexity and resource requirements increase
Solution Approach 1:
Complex security functions are extracted from the obsolete control system and implemented in separate security gateway components. This allows comprehensive security protection to be added without increasing the complexity of the original control system, as the security logic is isolated in dedicated hardware or software modules
Data Source
Figure 1a
Figure 1b
Figure 2
AI summary
The present disclosure provides systems and methods to stepwise increasing the IT security of elements of a technological system. In one example, the method comprises gathering data on technological systems and a plurality of elements comprising the technological system by intercepting traffic between the plurality of elements using data exchange protocols, identifying vulnerable elements of the technological system by one or more of: detecting suspicious actions on the vulnerable elements and statistical data relating to the elements, analyzing the vulnerable elements to generate a classification of severity of vulnerabilities of the vulnerable elements, identifying most vulnerable portions of the vulnerable elements as compared to other elements in the vulnerable elements, operating the most vulnerable portions of the vulnerable elements in a protected environment.